curl --request POST \
--url https://app.communicate.so/api/v1/account-credentials/{credentialId}/rotate \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"password": "<string>"
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({password: '<string>'})
};
fetch('https://app.communicate.so/api/v1/account-credentials/{credentialId}/rotate', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.communicate.so/api/v1/account-credentials/{credentialId}/rotate"
payload = { "password": "<string>" }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"name": "<string>",
"prefix": "<string>",
"scopes": [
"workspaces:read"
],
"expiresAt": "2023-11-07T05:31:56Z",
"token": "<string>"
}Replace a credential atomically without expanding its authority
Use an explicit credentials:write account bearer grant or a live email-verified application session, plus the current account password as fresh identity proof. Cookie writes require a trusted Origin. Machine callers cannot issue scopes beyond their own grant or outlive it. Creation and rotation return the secret once; metadata never includes it. Scope and expiry can only be narrowed. Issued credentials expire within 24 hours and no later than their issuer session; session revocation invalidates them.
curl --request POST \
--url https://app.communicate.so/api/v1/account-credentials/{credentialId}/rotate \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"password": "<string>"
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({password: '<string>'})
};
fetch('https://app.communicate.so/api/v1/account-credentials/{credentialId}/rotate', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.communicate.so/api/v1/account-credentials/{credentialId}/rotate"
payload = { "password": "<string>" }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"name": "<string>",
"prefix": "<string>",
"scopes": [
"workspaces:read"
],
"expiresAt": "2023-11-07T05:31:56Z",
"token": "<string>"
}Authorizations
Opaque user-bound ca_ account credential. Each request checks live account scopes, verified email, expiry, revocation and the issuer session. Not a workspace ck_ key or OAuth access token.
Headers
Required for cookie authentication: an exact trusted application origin configured by the server. Bearer requests do not require Origin.
Path Parameters
Body
1 - 1024Response
Replace a credential atomically without expanding its authority
^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$5 - 3001 - 20 elementsworkspaces:read, workspaces:write, workspaces:manage, members:read, members:write, teams:read, teams:write, invites:accept, agents:read, agents:write, sources:read, sources:write, learnings:read, learnings:write, grill:read, grill:write, notifications:read, notifications:write, credentials:read, credentials:write ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z|([+-](?:[01]\d|2[0-3]):[0-5]\d)))$One-time credential secret; not present in subsequent metadata reads.